Latest CVE Feed
-
8.8
HIGHCVE-2024-51503
A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges and execute arbitrary code on an affected machine. In certain circumstances, attackers that have legitim... Read more
Affected Products : deep_security_agent- Published: Nov. 19, 2024
- Modified: Sep. 04, 2025
-
7.5
HIGHCVE-2024-52802
RIOT is an operating system for internet of things (IoT) devices. In version 2024.04 and prior, the function `_parse_advertise`, located in `/sys/net/application_layer/dhcpv6/client.c`, has no minimum header length check for `dhcpv6_opt_t` after processin... Read more
Affected Products : riot- Published: Nov. 22, 2024
- Modified: Sep. 04, 2025
-
7.8
HIGHCVE-2025-7425
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID ... Read more
- Published: Jul. 10, 2025
- Modified: Sep. 04, 2025
- Vuln Type: Memory Corruption
-
9.0
CRITICALCVE-2024-3596
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Au... Read more
- Published: Jul. 09, 2024
- Modified: Sep. 04, 2025
-
7.5
HIGHCVE-2024-27919
Envoy is a cloud-native, open-source edge and service proxy. In versions 1.29.0 and 1.29.1, theEnvoy HTTP/2 protocol stack is vulnerable to the flood of CONTINUATION frames. Envoy's HTTP/2 codec does not reset a request when header map limits have been ex... Read more
Affected Products : envoy- Published: Apr. 04, 2024
- Modified: Sep. 04, 2025
-
7.5
HIGHCVE-2024-30255
Envoy is a cloud-native, open source edge and service proxy. The HTTP/2 protocol stack in Envoy versions prior to 1.29.3, 1.28.2, 1.27.4, and 1.26.8 are vulnerable to CPU exhaustion due to flood of CONTINUATION frames. Envoy's HTTP/2 codec allows the clie... Read more
Affected Products : envoy- Published: Apr. 04, 2024
- Modified: Sep. 04, 2025
-
7.5
HIGHCVE-2024-32475
Envoy is a cloud-native, open source edge and service proxy. When an upstream TLS cluster is used with `auto_sni` enabled, a request containing a `host`/`:authority` header longer than 255 characters triggers an abnormal termination of Envoy process. Envo... Read more
Affected Products : envoy- Published: Apr. 18, 2024
- Modified: Sep. 04, 2025
-
9.8
CRITICALCVE-2024-32017
RIOT is a real-time multi-threading operating system that supports a range of devices that are typically 8-bit, 16-bit and 32-bit microcontrollers. The size check in the `gcoap_dns_server_proxy_get()` function contains a small typo that may lead to a buff... Read more
- Published: May. 01, 2024
- Modified: Sep. 04, 2025
-
9.0
CRITICALCVE-2024-34346
Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. The Deno sandbox may be unexpectedly weakened by allowing file read/write access to privileged files in various locations on Unix and Windows platforms. For example, reading `... Read more
Affected Products : deno- Published: May. 07, 2024
- Modified: Sep. 04, 2025
-
7.8
HIGHCVE-2021-39810
In verifyDefaults of CardEmulationManager.java, there is a possible way to set a third party app as the default contactless payment app without user consent due to a missing permission check. This could lead to local escalation of privilege with no additi... Read more
Affected Products : android- Published: Oct. 30, 2023
- Modified: Sep. 04, 2025
-
6.1
MEDIUMCVE-2024-37161
MeterSphere is an open source continuous testing platform. Prior to version 1.10.1-lts, the system's step editor stores cross-site scripting vulnerabilities. Version 1.10.1-lts fixes this issue.... Read more
Affected Products : metersphere- Published: Jun. 11, 2024
- Modified: Sep. 04, 2025
-
6.1
MEDIUMCVE-2024-37304
NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Markdown content. While the platform properly filters out JavaScript from standard links, it does not adequa... Read more
Affected Products : nugetgallery- Published: Jun. 12, 2024
- Modified: Sep. 04, 2025
-
5.3
MEDIUMCVE-2024-37309
CrateDB is a distributed SQL database. A high-risk vulnerability has been identified in versions prior to 5.7.2 where the TLS endpoint (port 4200) permits client-initiated renegotiation. In this scenario, an attacker can exploit this feature to repeatedly... Read more
Affected Products : cratedb- Published: Jun. 13, 2024
- Modified: Sep. 04, 2025
-
6.5
MEDIUMCVE-2024-31228
Redis is an open source, in-memory database that persists on disk. Authenticated users can trigger a denial-of-service by using specially crafted, long string match patterns on supported commands such as `KEYS`, `SCAN`, `PSUBSCRIBE`, `FUNCTION LIST`, `COM... Read more
Affected Products : redis- Published: Oct. 07, 2024
- Modified: Sep. 04, 2025
-
8.8
HIGHCVE-2024-31449
Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack buffer overflow in the bit library, which may potentially lead to remote code execution. The problem exists ... Read more
Affected Products : redis- Published: Oct. 07, 2024
- Modified: Sep. 04, 2025
-
7.8
HIGHCVE-2024-24916
Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution with the installer's privileges (admin).... Read more
- Published: Jun. 19, 2025
- Modified: Sep. 04, 2025
- Vuln Type: Misconfiguration
-
7.8
HIGHCVE-2024-39755
A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0. A specially crafted PKG file can lead to execute priviledged operation. An attacker can make an unauthenticated HTTP request to trigger this vulnerab... Read more
Affected Products : anka_build_cloud- Published: Oct. 03, 2024
- Modified: Sep. 04, 2025
-
9.8
CRITICALCVE-2024-41433
PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component expression.ExplainExpressionList. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. NOTE: PingCAP maintains that the actual reprodu... Read more
Affected Products : tidb- Published: Sep. 03, 2024
- Modified: Sep. 04, 2025
-
4.3
MEDIUMCVE-2024-41434
PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal. This allows attackers to cause a Denial of Service (DoS) via a crafted input to the 'RemoveUnnecessaryFirstRow', it will check the expression between '... Read more
Affected Products : tidb- Published: Sep. 03, 2024
- Modified: Sep. 04, 2025
-
9.8
CRITICALCVE-2025-9752
A security vulnerability has been detected in D-Link DIR-852 1.00CN B09. Impacted is the function soapcgi_main of the file soap.cgi of the component SOAP Service. Such manipulation of the argument service leads to os command injection. The attack can be l... Read more
- Published: Sep. 01, 2025
- Modified: Sep. 04, 2025
- Vuln Type: Injection